Vulnerability Name: | CVE-2013-1886 (CCN-84479) | ||||||||
Assigned: | 2013-05-22 | ||||||||
Published: | 2013-05-22 | ||||||||
Updated: | 2015-08-26 | ||||||||
Summary: | Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-134 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-1886 Source: OSVDB Type: UNKNOWN 93613 Source: REDHAT Type: Vendor Advisory RHSA-2013:0856 Source: CCN Type: SA53524 Red Hat update for Red Hat Certificate System Source: CCN Type: Red Hat Certificate System Web site redhat.com | Certificate System Source: BID Type: UNKNOWN 60085 Source: CCN Type: BID-60085 Red Hat Certificate System CVE-2013-1886 Format String Vulnerability Source: SECTRACK Type: UNKNOWN 1029685 Source: CCN Type: Red Hat Bugzilla Bug 924870 CVE-2013-1886 Certificate System: pki-tps format string injection Source: CONFIRM Type: Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=924870 Source: CCN Type: Red Hat Bugzilla Bug 966190 pki-tps various flaws [epel-5] Source: XF Type: UNKNOWN rhcs-cve20131886-dos(84479) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |